Security model

All read, no write

An agent that can read your mail is useful. An agent that can also send or delete is a liability the moment an email tells it to. Emailgents is built on that distinction.

01

Agents can read, not act

The tool set has no send, reply, forward, move or delete. The single write, set_flags, toggles read and starred and reports exactly what changed. A prompt hidden in an email has nothing dangerous to call.

02

Least privilege per connection

MCP connections are tied to your signed-in account through OAuth. REST keys are scoped to chosen mailboxes and can be read-only. Either can be revoked in one click, and the next call fails.

03

Credentials encrypted at rest

App-specific passwords and OAuth refresh tokens are encrypted with keys that never leave the server, decrypted only inside the sync worker for the time it takes to talk to the provider.

04

Index, not archive

The default index holds headers, folder, flags, thread references, attachment names and a cleaned snippet for the last 90 days. Full bodies are fetched on demand and only cached, encrypted, if you turn it on per mailbox. Removing a mailbox deletes its index.

05

Every access logged

Each tool call and API request is recorded with the actor, the tool, the parameters and a correlation id, and shown on your Activity page. You can see what an agent read and when.

06

Provider-native revocation

Google and Microsoft access can also be revoked from your Google or Microsoft account; app-specific passwords can be revoked at Apple, Yahoo, Fastmail or any other provider. Access ends immediately either way.

What each provider connection can do

  • Gmail: Google's gmail.modify scope, used only to read and to toggle read/starred. Emailgents never sends, moves or deletes.
  • Outlook and Microsoft 365: Mail.ReadWrite, used only to read and to toggle read/flagged.
  • iCloud, Yahoo, Fastmail, AOL, Zoho, GMX, WEB.DE and IMAP: an app-specific password over IMAP with TLS; only the \Seen and \Flagged flags are ever written.

Provider scopes are coarser than what Emailgents uses; the product's own tool set is the real boundary, and it is visible in the MCP manifest and the API reference.

What is not there

  • No send, reply, forward, draft, move or delete tools.
  • No public share links for messages; the webUrl an agent receives opens only after you sign in.
  • No training on your mail and no selling of data.
  • No access for Emailgents staff without your explicit request during support.

Transparency

  • Every tool advertises readOnlyHint and idempotentHint annotations so clients can show the right confirmation prompts.
  • Search and thread answers carry coverage and freshness so an agent never presents a partial view as complete.
  • Errors are structured and never leak credentials or raw provider responses; each carries a correlation id you can quote to us.

Security questions

Can an email trick my agent into sending or deleting mail?

Not through Emailgents: there is no tool for it. An injection can at most mislead the agent about content, which the access log lets you review.

Where does the data live?

In an encrypted managed Postgres database behind the Emailgents service. Bodies are fetched from your provider on demand and only cached if you turn body caching on for a mailbox.

How do I remove everything?

Delete the mailbox in Emailgents to drop its index and credentials, or delete your account to remove all of it. Revoking at the provider ends access as well.

Do you have a responsible disclosure process?

Yes; report security issues through the contact listed in the app and we will acknowledge and work with you.

Read next

Your agents can read mail in five minutes.

One account, as many mailboxes as you need, every agent you run.